Show newer

so yeah, none of that hidden form field stuff is going to work

Show thread

fuck...
gitea-registration-proxy Signup request: bvhrcuxqnd (cedotze@gmail.com): "please leave this empty"

they actually use a browser, maybe even doing this shit by hand

Show thread

and now we wait..
there's been 2 actual spam signups again since I enabled registration this morning... so it shouldn't be long till I see some logging that isn't my testing

Show thread

lol yeah let's forward the request to the original outside gitea url, that totally won't get proxied back to us again

@schratze @bodems@chaos.social happens here too sometimes, weird firefox bug on *something* in the title text

@dumpsterqueer my naive approach right now is changing the signup template to put the email in a differently named form field, while adding a hidden field with the name="email". If that one is filled in (by a bot) the request is denied. We'll see if that's enough

writing proxy software is so fucking good because I can change behavior of software (Synapse, Gitea) without having to actually interact with their codebases

@tastytea i'm implementing it now, with a hacky proxy so I don't have to interact with the gitea codebase itself :)

@wmd@chaos.social yeah that's not great. As @tastytea brought up the gitea-native captchas are even worse in that aspect tho, because they're just image based captchas :/

reCaptcha is a no-go of course. Gitea also has image captchas but from issues it seems it's really not so reliable at keeping spam out

Show thread

Does anyone have thoughts on hCaptcha? Gitea gets absolutely flooded with spam signups without a captcha, but I'd really like to make registration open again :boost_requested:

Show older
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.